Security and Compliance Flashcards
7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Compliance flashcards as text
What is a Software Bill of Materials (SBOM) used for in a DevSecOps context?
Answer: Providing a complete inventory of all components and dependencies in a software artifact
An SBOM is a formal, machine-readable inventory of all components, libraries, and dependencies in a software product, enabling rapid identification of affected systems when new CVEs are disclosed.
Which Azure service combination enables automatic vulnerability scanning of container images when they are pushed to the registry?
Answer: Azure Container Registry with Microsoft Defender for Containers
Enabling Microsoft Defender for Containers on Azure Container Registry triggers automatic vulnerability scans of images on push, surfacing CVEs before images are deployed.
Which Azure Policy effect automatically deploys a resource or configuration to bring a non-compliant resource into compliance?
Answer: DeployIfNotExists
The DeployIfNotExists effect triggers a remediation deployment when a resource is found to be missing required configurations, automatically restoring compliance.
In DevSecOps, what does Infrastructure as Code (IaC) scanning accomplish?
Answer: Analyzing IaC templates like Terraform or Bicep for security misconfigurations before deployment
IaC scanning tools (e.g., Checkov, tfsec, Microsoft Defender for DevOps) analyze Terraform, ARM, and Bicep templates for misconfigurations and policy violations before infrastructure is provisioned.
Which configuration is recommended to prevent forked repository pull requests from accessing protected pipeline secrets in Azure Pipelines?
Answer: Configure fork build validation to limit secret access and require manual approval for fork PRs
Azure Pipelines fork protection settings can prevent secrets from being passed to fork PR builds and require a team member to manually approve the run before it starts.
What is the recommended modern approach for authenticating Azure DevOps pipelines to Azure without storing service principal secrets?
Answer: Using workload identity federation to eliminate stored secrets
Workload identity federation lets Azure DevOps service connections authenticate to Azure using federated tokens instead of stored secrets or certificates, removing the need to manage credential rotation.
Which framework provides Microsoft's prescriptive security best practices and control mappings specifically for Azure and multi-cloud environments?
Answer: Microsoft Cloud Security Benchmark (MCSB)
The Microsoft Cloud Security Benchmark (MCSB) maps Azure security recommendations to common industry standards (NIST, CIS, PCI) and is the primary guidance Microsoft publishes for securing Azure workloads.